Businesses and event operators preparing for Martyn’s Law have been given further detail on when qualifying premises and events must notify the regulator after the legislation comes into force.
The Security Industry Authority, which will regulate the Terrorism (Protection of Premises) Act 2025, said qualifying premises will have three months from commencement of the relevant provisions to submit their initial notification.
After that period, changes relating to qualifying premises must be reported within 28 days. The responsible person for a qualifying event will generally need to notify the SIA within 14 days of the event date being made publicly available.
The responsible person may authorise another individual or service provider to submit a notification, but legal accountability remains with the person, company, or organisation that controls the premises or event for the relevant use.
Control generally involves occupying the premises and having the ability to make decisions about their management and use, including who can enter or remain on site. Contractual arrangements between owners, tenants, venue operators, promoters, and event organisers may therefore need to be reviewed to establish where responsibility sits.
Martyn’s Law creates two principal tiers for qualifying premises. The standard tier applies where it is reasonable to expect between 200 and 799 people, including staff, to be present at the same time. Enhanced-tier duties normally apply where the expected number is 800 or more.
Qualifying events are subject to enhanced-tier requirements where at least 800 people may be present and other statutory conditions are met, including controls on entry. Some premises, including certain education, childcare, and places-of-worship settings, are treated differently under the legislation.
Standard-tier operators will need to notify the SIA and maintain appropriate procedures, so far as reasonably practicable, for evacuation, invacuation, lockdown, and communication during an attack or an incident in the immediate vicinity.
Enhanced-tier premises and qualifying events face additional requirements. These include assessing public-protection risks, putting reasonably practicable measures in place to reduce vulnerability and physical harm, documenting compliance, and designating a senior individual where the responsible person is an organisation.
The SIA said: “Martyn’s Law is not about stopping events from happening. It is about making them safer.”
The notification timetable gives operators a clearer basis for implementation planning, but the regulator’s digital portal is still being developed. The SIA is recruiting volunteers to test the system and draft regulatory guidance before wider publication.
Organisations likely to be in scope can use the preparation period to map premises, calculate expected attendance, identify responsible persons, review leases and operating agreements, and assess existing emergency and security procedures. Larger groups may need a central register covering multiple sites, varying capacities, and changes in control.
Capacity calculations may require more than reference to a venue’s advertised limit. Operators will need to consider the number of staff and other people who can reasonably be expected to be present, how different areas are used, and whether separate activities fall under different control arrangements.
The requirement to notify is only one part of compliance. Companies will also need evidence that procedures are appropriate to the premises and that staff understand their roles. Enhanced-tier operators may require more formal risk assessment, governance, documentation, and oversight.
Procedures must also be capable of operating in practice. A written plan may have limited value where employees cannot access it, responsibilities are unclear, communication systems fail, or contractors and temporary workers have not been included in training.
Procurement and supplier arrangements could be affected. Security contractors, facilities managers, event producers, landlords, insurers, technology providers, and professional advisers may all contribute to preparation, although responsibility cannot simply be transferred through outsourcing.
Contracts may need to specify who maintains attendance information, manages entry systems, updates procedures, provides training, and reports changes to the responsible person. Those arrangements are particularly important where a venue hosts events operated by several promoters or where property management is divided between landlords and tenants.
The Act received Royal Assent on 3 April 2025 and is expected to have an implementation period of at least 24 months. The SIA’s August update said the legislation will not come into force until 2027, allowing further time for guidance, portal development, and sector engagement.
Operators should not treat commencement as the beginning of preparation. Establishing control, capacity, tier, procedures, and record-keeping across complex premises can require input from legal, operational, security, property, human-resources, and technology teams.
Multi-site organisations may also need a consistent governance structure that allows local managers to adapt procedures to their premises while giving the board or senior management confidence that duties are being met across the group.
The latest guidance reduces uncertainty around the first regulatory deadline. Further detail will still be required on the notification platform, enforcement approach, final commencement dates, and how the SIA will assess whether measures are reasonably practicable for different types of premises and events.
Preparation undertaken before commencement can still be proportionate to the level of risk. The legislation does not require every site to adopt identical physical-security measures, but it will require organisations to understand their responsibilities, maintain workable procedures, and demonstrate how decisions were reached.




You must be logged in to post a comment.